hb46pp
hb46pp is a Rust client for the
HTTP-Based IPv4 over IPv6 Provisioning Protocol used to discover
provisioning parameters for IPv4-over-IPv6 methods. It implements bootstrap TXT
discovery, request and response validation, IPv6-only HTTP transport, protocol
redirects, and retry timing and migration-state guidance.
Provisioning data for each supported IPv4-over-IPv6 method is retained as JSON. Applications select a method and interpret its parameters.
Example
The default features provide a Hickory DNS resolver and a
Reqwest HTTP transport with a total timeout of 30 seconds per
provisioning request. DefaultClient::try_new uses the default client settings,
but callers can customize them with DefaultClient::builder.
#
#
The library provides retry timing and uses ClientError::retry_action to
distinguish disabling from preserving the previous migration mechanism. It does
not choose a random delay, sleep, monitor network changes, modify network
configuration, or persist data. Those responsibilities remain with the
application.
Features
default-client(default): default DNS resolver and HTTP transport.client: protocol flow and adapter traits without concrete network adapters.default-resolver: Hickory-based discovery resolver.default-transport: Reqwest-based IPv6-only HTTP transport.- No features: protocol models and validation only.
Custom transports must use IPv6, apply the requested TLS policy, avoid automatic redirects, and bound response resource usage.
Security
HB46PP bootstrap discovery trusts the DNS response for 4over6.info. Requiring
certificate validation protects communication with the hostname in that
response, but does not independently authenticate that DNS selected the
intended provider. Applications should use HB46PP discovery only where the
access-network DNS is trusted.
The client rejects bootstrap policy t=a by default because it permits HTTP or
HTTPS without certificate validation. Applications that require compatibility
with such a provider must explicitly select
ProvisioningAuthenticationPolicy::AllowUnauthenticated.
License
Licensed under either of the following:
- Apache License, Version 2.0 (LICENSE-APACHE)
- MIT License (LICENSE-MIT)